mirror of
https://github.com/stablyai/orca.git
synced 2026-09-28 00:02:41 +00:00
* perf(relay): release rejected first-frame connections [trade-off] * fix(relay): bound the director's rejected and redirected first-frame closes too The parent PR routed four cell-side first-frame rejections through closeRelayWebSocket but left two raw socket.close() calls in the same handler. A real-socket probe shows both still pin a connection unit for ws's full 30s close timer when the peer ignores the close frame: - 'invalid invite' is reachable by an unauthenticated peer with a well-formed but bogus credential, so the exhaustion the parent PR claims to prevent stayed reachable on the director; - 'connect to assigned cell' is the happy path for every phone's first director contact, so it is the highest-volume unbounded close here. closeWithDrain gets the same treatment; host-session-registry already closes the identical drain through the helper. Also records that the bounded close is not a user-facing trade-off: the close frame is written before the force-close timer can fire and TCP delivers it ahead of the FIN, so an abandoned peer still reads code and reason over a graceful close. The new regression asserts that, plus exactly-once release across concurrent bursts and rejection racing the peer's own disconnect (the ledger does not clamp at zero, so a double release would surface as a negative count). * refactor(relay): drop the unused closeWithDrain helper `closeWithDrain` has no callers anywhere in the repo, and its `graceMs` parameter promised a caller-supplied drain window that the body no longer honours: routing it through `closeRelayWebSocket` force-terminates after 1s regardless, so a future caller passing `graceMs: 30_000` would have had its drain silently cut short while the signature still claimed otherwise. The real drain path is `host-session-registry`, which sends the same `resolve-director` drain and closes it there. Delete the dead duplicate rather than bound a helper whose contract says "graceful". Co-Authored-By: Claude <noreply@anthropic.com> * docs(relay): call the bounded close's rejection delivery best effort, not guaranteed The helper claimed the forced terminate costs an abandoned peer nothing it can observe, and the test presented its fast-peer assertion as proof. Neither holds in general: `ws` writes the close frame to the socket and `terminate()` destroys that socket a second later, so under backpressure the frame — and any `relay-moved` message queued ahead of it — can go unsent even to a peer that never stopped reading. Qualifies both comments to describe delivery as best effort and name the backpressure case. The fast-peer assertion is valid and stays exactly as it was; only its stated scope narrows, and the test is renamed to say which peer it speaks for. What the bound actually buys — a stalled peer cannot hold admission — is now stated on its own rather than resting on a delivery claim. Co-Authored-By: Claude <noreply@anthropic.com> --------- Co-authored-by: Claude <noreply@anthropic.com>